Privacy Policy
Last updated: September 2026
This Privacy Policy applies to the DRAPAI website (drapai.com) and DRAPAI mobile applications. It describes how we collect, use, and protect your personal information when you use our virtual try-on and related services (“Service”).
1. Who We Are (Controller) and Contact
The controller responsible for processing personal data for the Service is Demirhan Kul (operating DRAPAI). Business address: Yeni Mahalle Caddesi No:98, Daire: 1 Kat: 1, Sarıyer 34450, Türkiye. For account and data deletion requests, you can also use our public form at drapai.com/delete-account.
Legal contact: [email protected]. Privacy contact: [email protected].
2. Information We Collect
- Account and profile data: Such as email address and basic account details you provide when you create or manage an account.
- User content: Photos or images you upload for virtual try-on and the images generated as outputs. These files are processed to produce results through our pipeline (currently: cloud database/storage via Supabase; workflow automation via n8n Cloud; AI virtual try-on image generation via Google Cloud Vertex AI). Images may contain facial or other physical characteristics; we process image content only to provide the requested virtual try-on and related functionality and do not use it for facial recognition or identification of individuals. We keep cloud-held visual assets only for a limited retention window: generated outputs are typically retained for about 14 days after a job finishes; failed or aborted jobs are typically eligible for cleanup within about 72 hours; unfinished provisional uploads are typically removed within about 1 hour. Files are transmitted over TLS, stored in private access-controlled storage scoped to your account, and we do not use uploaded photos or generated images to train or fine-tune generative AI models. Optional wardrobe or pose libraries you create in the mobile app are stored only on your device and are not transmitted to our servers unless you explicitly select them for a try-on or other cloud feature.
- Usage and diagnostics: Information about how you use the Service (e.g. feature usage) and limited logs needed for reliability, security, and troubleshooting.
- Device and app data (mobile): Device identifiers and app events where needed for security, functionality, and analytics. For example, the mobile app may log product events (like opening Studio or exporting) associated with your account user ID to monitor performance, detect abuse, and improve product reliability.
- Website data (cookies/local storage): On the website, we may use cookies or local storage for essential functionality and, if you consent, analytics (for example, Google Analytics with IP anonymization enabled where supported). See our Cookie Policy for details.
- Communications: Messages you send us (support requests, contact forms, deletion requests).
- Payments: If you purchase a subscription, we receive records needed to provide the purchase (for example, transaction identifiers and subscription status). Payment processing may be handled by the relevant platform (e.g. Apple App Store / Google Play) or our payment providers depending on where you purchase.
3. How We Use Your Information
We use personal data to provide and operate the Service (including generating outputs), maintain your account, process subscriptions and entitlements, communicate with you (including service and security notices), provide support, prevent fraud and abuse, and comply with legal obligations. We do not use uploaded photos or generated images to train or fine-tune generative AI models. We may process limited technical and usage information (for example, feature usage, error rates, and diagnostics) to monitor performance, detect abuse, troubleshoot problems, and improve the Service.
4. Legal Bases (EEA/UK and Similar Laws)
- Performance of a contract: Account creation and management; generating requested try-on results; delivering outputs; subscription and entitlement management.
- Legitimate interests: Security, fraud and abuse prevention, service diagnostics and reliability monitoring, and limited product improvement based on technical/usage telemetry (not training generative models on your photos).
- Consent: Optional website analytics cookies and similar non-essential technologies, where required.
- Legal obligation: Retention or disclosure required by applicable law, court order, or competent authority.
5. Sharing and Disclosure
We share personal data with service providers that help us operate the Service under contracts that require appropriate data protection. Depending on the feature, this currently includes: cloud hosting, authentication, and object storage (Supabase; United States, us-east-2); workflow automation for generation jobs (n8n Cloud); AI image generation for virtual try-on (Google Cloud Vertex AI; United States, us-central1); website analytics if you consent (for example, Google Analytics); email delivery for contact and deletion forms (currently Resend); and payment/subscription processing by Apple App Store and/or Google Play when you purchase in the apps. Providers receive only the data needed for their role (for example, Vertex AI receives image content required to generate a try-on result). We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets. We do not sell personal information to third parties for their own marketing.
6. International Transfers
Certain service providers may process personal data outside the European Economic Area or the United Kingdom. In particular, core hosting and AI image-generation processing currently occur in the United States (see Section 5 and our Subprocessors page). Where required by applicable law, we rely on an adequacy decision, Standard Contractual Clauses, or another legally recognised transfer mechanism.
7. Data Retention
We retain account data for as long as your account is active and as needed to provide the Service and comply with legal obligations. Cloud-held visual assets (uploaded images, garment images, and generated images) are deleted from our active storage on an automated schedule: generated outputs are typically removed about 14 days after a job finishes; failed or aborted jobs are typically cleaned within about 72 hours; unfinished provisional uploads are typically removed within about 1 hour. Residual copies may persist briefly in caches or provider-side recovery systems after deletion from active storage. On our current Supabase plan, retained downloadable daily database backups are not provided; if we upgrade to a plan with scheduled backups, residual database retention will follow that plan’s backup window (for example, up to 7 days on Supabase Pro). Job metadata (such as status and timestamps) may be kept longer for operations, billing, security, and legal compliance. Device-local wardrobe or pose files remain on your device until you delete them or uninstall the app. Analytics and logs may be retained in anonymised or aggregated form.
8. Data Security
We use technical and organisational measures including TLS in transit, private storage with account-scoped access controls, least-privilege access for operations, and regular security reviews. Image processing requires our systems and processors to read file content to generate outputs; we do not claim end-to-end encryption where we cannot decrypt stored files. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
9. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict certain processing. You can update some account details in the Service, use our deletion form at drapai.com/delete-account, or contact us. Where we rely on consent (for example, optional analytics cookies on the website), you can withdraw consent at any time by changing your preferences. In the EEA/UK, you may have the right to lodge a complaint with a supervisory authority. We will respond to requests in accordance with applicable law.
10. Children
The Service is not directed at children under 13, or the higher minimum age required by applicable law in the relevant jurisdiction. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us and we will delete it.
11. Changes and Contact
We may update this Privacy Policy from time to time. We will post the updated version on the website and in the app and update the “Last updated” date. Material changes may be communicated by email or in-app notice.
12. Privacy Contact
For privacy-related inquiries or to exercise your rights, contact us at [email protected]. See also our Subprocessors page.